Re: [Tigervnc-devel] vncviewer password prompt text mode instead of window

2011-05-05 Thread Pierre Ossman
On Wed, 4 May 2011 21:57:44 + Cook, Jason jason.c...@wesd.org wrote: This question has been asked before in 2009: Jeff Kowalczyk Thu, 17 Sep 2009 14:20:27 -0700⁠ (Begin quote) Tightvnc-1.3.10 prompted for a password in the terminal from which it was started. When using a -via ssh

Re: [Tigervnc-devel] potential vulnerability in TLS secType?

2011-05-05 Thread Adam Tkac
Hello Brian, thanks for notification about this issue, you are right that password might been sent over network without proper validation of the X.509 certs. Can you please test if attached patch solves this issue? It is Martin's patch with little modification (result is rdr::U32 instead of

[Tigervnc-devel] [ tigervnc-Feature Request Tracker-3297845 ] vncviewer multiple fullscreen

2011-05-05 Thread SourceForge.net
Feature Request Tracker item #3297845, was opened at 2011-05-05 12:38 Message generated for change (Tracker Item Submitted) made by timtatanka You can respond by visiting: https://sourceforge.net/tracker/?func=detailatid=1126849aid=3297845group_id=254363 Please note that this message will

Re: [Tigervnc-devel] potential vulnerability in TLS secType?

2011-05-05 Thread Brian Hinz
Wouldn't this (also untested) work as well, and have the advantage of relying on gnutls to verify that the handshake was completed? diff -Nr -C 6 rfb.unix/CSecurityTLS.cxx.bak rfb.unix/CSecurityTLS.cxx *** rfb.unix/CSecurityTLS.cxx.bak 2011-05-05 06:54:11.018963720 -0400 ---

Re: [Tigervnc-devel] potential vulnerability in TLS secType?

2011-05-05 Thread Brian Hinz
Adam, Martin's patch seems to work (my suggestion did not). -brian On Thu, May 5, 2011 at 5:45 AM, Adam Tkac at...@redhat.com wrote: Hello Brian, thanks for notification about this issue, you are right that password might been sent over network without proper validation of the X.509 certs.

Re: [Tigervnc-devel] potential vulnerability in TLS secType?

2011-05-05 Thread Martin Koegler
On Thu, May 05, 2011 at 07:01:49AM -0400, Brian Hinz wrote: Wouldn't this (also untested) work as well, and have the advantage of relying on gnutls to verify that the handshake was completed? diff -Nr -C 6 rfb.unix/CSecurityTLS.cxx.bak rfb.unix/CSecurityTLS.cxx ***

[Tigervnc-devel] Report on TigerVNC autorepeat issue.

2011-05-05 Thread Robert Goley
I have finally tested DRC's new build. The autorepeat functionality is working now from a windows client to a linux server. It does seem to take a bit longer for the second character to kick in but I have been working without autorepeat in VI for so long now that it is

[Tigervnc-devel] [ tigervnc-Bug Tracker-3297994 ] password focus behaviour

2011-05-05 Thread SourceForge.net
Bug Tracker item #3297994, was opened at 2011-05-05 10:31 Message generated for change (Tracker Item Submitted) made by cookja You can respond by visiting: https://sourceforge.net/tracker/?func=detailatid=1126848aid=3297994group_id=254363 Please note that this message will contain a full copy of

[Tigervnc-devel] [ tigervnc-Feature Request Tracker-3297998 ] password prompt on stdin/stdout

2011-05-05 Thread SourceForge.net
Feature Request Tracker item #3297998, was opened at 2011-05-05 10:44 Message generated for change (Tracker Item Submitted) made by cookja You can respond by visiting: https://sourceforge.net/tracker/?func=detailatid=1126849aid=3297998group_id=254363 Please note that this message will contain a